AI agents are becoming embedded in how people work and manage their digital lives, automating tasks, executing commands, and operating with deep access to personal data and devices. The benefits are real, but so are the risks.
Unlike the malware threats of the early internet, a compromised AI agent does not just infect a file. It makes decisions and takes action, meaning a single manipulated instruction can have immediate real-world consequences.
“People are giving AI agents significant access to their machines, accounts and personal information because that’s what makes them powerful,” said Travis Witteveen, head of products and portfolios at Gen. “But until now, there’s been no way to verify what those agents are about to do and the potential harm they could cause with one bad decision or click.”
Witteveen is referring to the new Norton AI Agent Protection product that is designed to help people safely use AI tools that can take action on their behalf.
The product attempts to offer increased security and visibility into AI agent action by delivering real-time oversight of every action an AI agent takes, creating a checkpoint between decisions and execution.
Gen’s, the parent company of Norton, Threat Labs underscores the urgency, identifying approximately hundreds of malicious skills in public agent registries.
Even well-intentioned agents can expose credentials, introduce compromised dependencies, and execute destructive commands; acting quickly and autonomously, with unchecked access to sensitive data. By the time someone notices, it is often too late.
Recommended reading
- AI Agents Are Transforming Enterprise AI Adoption
- AI Agents Go Mainstream, But Fragmentation Is a Major Obstacle
- Can AI Agents Escape Their Sandboxes?
- New Whitepaper Reveals Urgent Agentic AI Security Risks
- Report: 1.5 Million Enterprise AI Agents At Risk of ‘Going Rogue’
The push for AI and the swift transition from pilots and chatbots to AI agent implementation have left security teams scrambling to keep up with mounting pressures from cyber threat actors and continual insider faults.
Adding AI into the mix has been a double-edged sword for security teams – while AI has been employed for years to detect threats, agentic and autonomous systems can open up new avenues for threat actors to infiltrate these novel systems.





